Title : Blender "imb_loadhdr()" File Handling Buffer Overflow Vulnerability VUPEN ID : VUPEN/ADV-2008-1308 CVE ID : CVE-2008-1102
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-04-21
Technical Description
A vulnerability has been identified in Blender, which could be exploited by attackers to cause a denial of service or compromise an affected system. This issue is caused by a buffer overflow error in the "imb_loadhdr()" [source/blender/imbuf/intern/radiance_hdr.c] function when processing a malformed Radiance RGBE image, which could be exploited by attackers to crash an affected application or execute arbitrary code by tricking a user into opening a specially crafted Blender (*.blend) file.